Jump to content


PrimaryCriddle

Member Since 18 May 2009
Offline Last Active May 27 2009 03:48 PM
-----

Posts I've Made

In Topic: Miekiemos is a god

19 May 2009 - 11:15 AM

Ok, I retract my previous statement. You ARE a god! Everything is back intact and MB updated! I have a couple last questions. I assume this is it for your help. Do you need anything more after I sent you that zip file? I also have been trying to use CyberDefender for anti-virus(this problem has hindered that effort). Is this something that would work well in conjunction with MB?

I need to go to work now, so I'll check back at the end of the day. Thanks again for all you did. I subscribed to MB on a recommendation from a geek friend and I will sing its praises to anyone who will listen.

In Topic: ClientMan & GameVance infections

18 May 2009 - 07:58 PM

OK, here goes.

I uninstalled StopZilla. I was only grasping at straws at possible solutions. I have you now!

All of the items including the two startup items are fixed.

Drivers32 key:
Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32
Class Name: <NO CLASS>
Last Write Time: 4/23/2009 - 7:58 PM
Value 0
Name: midimapper
Type: REG_SZ
Data: midimap.dll

Value 1
Name: msacm.imaadpcm
Type: REG_SZ
Data: imaadp32.acm

Value 2
Name: msacm.msadpcm
Type: REG_SZ
Data: msadp32.acm

Value 3
Name: msacm.msg711
Type: REG_SZ
Data: msg711.acm

Value 4
Name: msacm.msgsm610
Type: REG_SZ
Data: msgsm32.acm

Value 5
Name: msacm.trspch
Type: REG_SZ
Data: tssoft32.acm

Value 6
Name: vidc.cvid
Type: REG_SZ
Data: iccvid.dll

Value 7
Name: vidc.I420
Type: REG_SZ
Data: msh263.drv

Value 8
Name: vidc.iv31
Type: REG_SZ
Data: ir32_32.dll

Value 9
Name: vidc.iv32
Type: REG_SZ
Data: ir32_32.dll

Value 10
Name: vidc.iv41
Type: REG_SZ
Data: ir41_32.ax

Value 11
Name: vidc.iyuv
Type: REG_SZ
Data: iyuv_32.dll

Value 12
Name: vidc.mrle
Type: REG_SZ
Data: msrle32.dll

Value 13
Name: vidc.msvc
Type: REG_SZ
Data: msvidc32.dll

Value 14
Name: vidc.uyvy
Type: REG_SZ
Data: msyuv.dll

Value 15
Name: vidc.yuy2
Type: REG_SZ
Data: msyuv.dll

Value 16
Name: vidc.yvu9
Type: REG_SZ
Data: tsbyuv.dll

Value 17
Name: vidc.yvyu
Type: REG_SZ
Data: msyuv.dll

Value 18
Name: wavemapper
Type: REG_SZ
Data: msacm32.drv

Value 19
Name: msacm.msg723
Type: REG_SZ
Data: msg723.acm

Value 20
Name: vidc.M263
Type: REG_SZ
Data: msh263.drv

Value 21
Name: vidc.M261
Type: REG_SZ
Data: msh261.drv

Value 22
Name: msacm.msaudio1
Type: REG_SZ
Data: msaud32.acm

Value 23
Name: msacm.sl_anet
Type: REG_SZ
Data: sl_anet.acm

Value 24
Name: msacm.iac2
Type: REG_SZ
Data: C:\WINDOWS\system32\iac25_32.ax

Value 25
Name: vidc.iv50
Type: REG_SZ
Data: ir50_32.dll

Value 26
Name: msacm.l3acm
Type: REG_SZ
Data: C:\WINDOWS\system32\l3codeca.acm

Value 27
Name: wave
Type: REG_SZ
Data: serwvdrv.dll

Value 28
Name: wave1
Type: REG_SZ
Data: wdmaud.drv

Value 29
Name: midi
Type: REG_SZ
Data: wdmaud.drv

Value 30
Name: mixer
Type: REG_SZ
Data: wdmaud.drv

Value 31
Name: aux
Type: REG_SZ
Data: C:\WINDOWS\system32\..\mdkxo.brq


Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server
Class Name: <NO CLASS>
Last Write Time: 8/16/2005 - 9:38 AM

Key Name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\Terminal Server\RDP
Class Name: <NO CLASS>
Last Write Time: 8/16/2005 - 9:38 AM
Value 0
Name: wave
Type: REG_SZ
Data: rdpsnd.dll

Value 1
Name: mixer
Type: REG_SZ
Data: rdpsnd.dll

Value 2
Name: MaxBandwidth
Type: REG_DWORD
Data: 0x56b9

Value 3
Name: wavemapper
Type: REG_SZ
Data: msacm32.drv

Value 4
Name: EnableMP3Codec
Type: REG_DWORD
Data: 0x1

Value 5
Name: midimapper
Type: REG_SZ
Data: midimap.dll

And lastly there was a new regedit created. I think that was it. Thank you soooooooo much for your help! I at least feel we are making progress.
-Craig

In Topic: Trojan.bho strikes

18 May 2009 - 12:41 PM

Close this post. I've just read your instructions on how to use your help and will do it properly with a new topic. Thanks.

In Topic: Trojan.bho strikes

18 May 2009 - 12:21 PM

Sorry about the multiple posts. My bad-I've got to quit random clicking! I see the section on removing specific viruses and found the couple I have, but I can't update the virus definitions with these in place. Is there some way to manually add a file (copy onto a disc and physically moving it to the infected machine) to get the latest definitions?

In Topic: Trojan.bho strikes

18 May 2009 - 12:15 PM

View PostPrimaryCriddle, on May 18 2009, 05:06 PM, said:

In reading these couple of posts, it looks like I CAN be helped! I have been infected by a couple of things that certainly seem to be gaining intelligence. I can no longer update Malwarebytes as it looks like I can not connect to you. I am on another computer just to communicate. It appears like a Windows update when shutting down that reinfects whatever it does. Malwarebytes was the only package that found all of the registry key infections, but now that I can't update the definitions, I'm really hosed. Is the ComboFix solution a possibility?